Who is Participating?

There is always new ways of attacks. But, I can think of the following steps that as a general rule should mitigate against "broadcast" attacks:

1. Turn off directed broadcasts: on Cisco routers this is done by "no ip directed-broadcast" interface command.
2. Turn off "chargen" and "ICMP Echo reply"
3. Do not allow forwarding of broadcast traffic on routers. This is off by default. Make sure it stays that way.
4. Use " ip verify unicast reverse-path " command.
5. Use an IDS at the perimeter of the network to detect attacks.